CVE-2018-19653 describes a vulnerability in HashiCorp Consul versions 0.5.1 through 1.4.0, where agent-to-agent RPC communication can occur in cleartext due to insufficient documentation of the verify_outgoing setting. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high confidentiality impact, allowing an attacker to intercept sensitive communications. While there is no evidence of active exploitation, exploit code, or significant community discussion, HashiCorp has provided reconfiguration steps to mitigate the issue without requiring a software upgrade.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.5.1, <= 1.4.0CPE matchmatch criteria | cpe:2.3:a:hashicorp:consul:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.